REDHAT-BUG-1383211: Null Pointer Dereference
CVE-2016-8568
Read out-of-bounds in gitoidnfmt: https://github.com/libgit2/libgit2/issues/3936
CVE-2016-8569
DoS using a null pointer dereference in gitcommitmessage: https://github.com/libgit2/libgit2/issues/3937
Proposed patch:
https://github.com/libgit2/libgit2/pull/3956
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1383211?
The severity of REDHAT-BUG-1383211 is categorized as high due to the potential for out-of-bounds read vulnerabilities.
How do I fix REDHAT-BUG-1383211?
To fix REDHAT-BUG-1383211, update to the latest version of libgit2 that addresses CVE-2016-8568.
What are the potential risks associated with REDHAT-BUG-1383211?
The risks associated with REDHAT-BUG-1383211 include data leaks or application crashes due to out-of-bounds memory access.
Which versions of libgit2 are affected by REDHAT-BUG-1383211?
Versions of libgit2 prior to the security fix for CVE-2016-8568 are affected by REDHAT-BUG-1383211.
Is there an exploit available for REDHAT-BUG-1383211?
Yes, there may be potential exploits available that leverage the out-of-bounds read vulnerability described in REDHAT-BUG-1383211.